Policy
Hiring for AI You Have Not Approved Internally
Requiring AI skills in a job post while security blocks the tools publishes a contradiction; decide which policy is real before the req opens. If the block is permanent, the role needs the judgment underneath the tool: scoping a task, checking an output, noticing a confident wrong answer. Write the requirement in those words and drop the tool names. If the block is temporary, name the approved stack and the date it arrives; a hire who spends a quarter on a personal phone is a retention problem the posting created.
The takeAn unapproved stack is a compensation question before it is a hiring question. Postings that name AI skills advertise higher salaries, and that premium buys a person who expects to use the thing on day one. Paying it for a seat where the tool is blocked at the proxy is the most expensive way available to discover that the security review never finished. That is a sequencing failure priced as a talent expense, and the bill arrives whether or not anyone notices the order was wrong.
Where Olive fits
Open a role and see what the work shows
The same six dimensions describe capable AI work on a team as in a hiring round: framing before generating, sourcing the claim a decision rests on, keeping the judgment that should not be handed over, and checking an output against something outside the conversation. Olive reads those from one working session rather than from a self-assessment.
Rank your shortlistWhich policy is actually in force?
Whichever one the proxy enforces. A security block is an operating fact and an AI-skills requirement is an aspiration, so when they disagree the block wins and the req is the thing that is wrong. Answer it in one meeting before the posting goes out: is the block permanent, is it temporary with a date, or has it already been lifted for some teams and never announced?
The third answer is the most common and the least documented. Firm-level adoption is real but not universal: the Census Bureau's Business Trends and Outlook Survey put AI use among US businesses at 19.8% as of 3 May 2026, with 37% of firms of at least 250 employees reporting use against about 14% in retail trade 1. The unit there is the firm, and the question asks about the previous two weeks, so it says nothing about how heavily an adopting firm uses anything. What it does say is that approved use clusters in large employers and is still a minority even there, so the answer for your own company has to be looked up.
Worker-level numbers run higher, which is the gap that matters here. In nationally representative US surveys from late 2024, 23% of employed respondents had used generative AI for work at least once in the previous week and 9% used it every work day 2. Self-reported, a low bar, and already old. The practical reading is that a blocked stack rarely means nobody is using anything; it means the use is unlogged, unsupported, and happening on hardware you do not administer.
So the meeting has one output: a sentence naming the policy, an owner, and a date. Without it, the req is written against a guess, and the guess is usually the more flattering of the two.
Write the requirement in judgment terms, not tool names
Name the behavior the role needs and leave the product out. Scoping a task before generating anything, demanding a source for the claim the decision rests on, keeping the judgment that should not be delegated, and checking an output against something outside the conversation. Every one of those is testable with a spreadsheet and a phone, and none of them expires when the approved vendor changes.
The swap, in the words a req actually uses:
- Instead of "3+ years using ChatGPT and Claude daily", write "can take a vague request, decide what needs checking before anything ships, and say how they checked it."
- Instead of "prompt engineering experience", write "can tell when a confident answer is wrong in a domain they know, and show the check."
- Instead of "AI-first mindset", write nothing. It is not a requirement, and it screens for people who repeat it.
The wording holds up legally as well as practically. In the US, 42 U.S.C. 2000e-2(k), added by the Civil Rights Act of 1991, says an employer facing a demonstrated disparate impact must show the challenged practice is job related for the position in question and consistent with business necessity 5. That burden lands only after a complaining party makes the impact showing, and it reaches Title VII grounds rather than age or disability, which have their own statutes. Describing the work is the version of a requirement an employer can stand behind. Check specific wording with counsel.
The bar does not drop when the tool names come out. Employers already price these skills into what they advertise: Lightcast reports that postings mentioning AI skills advertise salaries 28% higher than postings that do not, roughly $18,000 more a year, and that in 2024 over half of postings requesting AI skills sat outside IT and computer science 3. That is a raw comparison of advertised salaries between two groups of postings rather than a like-for-like wage estimate, and AI-mentioning postings skew senior. Read it as evidence that the demand is broad, not that the premium is causal.
Which seats genuinely need any of this is a separate question, and worth asking before the wording one: which roles at a company actually need AI skills usually returns a shorter list than the org chart suggests.
What to do when the block is temporary
Name the stack and the date in the posting, then hold the date. A candidate who reads "daily work with an assistant" and arrives to a blocked proxy has been misled whatever the intention was, and the first ninety days go on working around it. Writing "approved tooling lands in Q1; until then the work runs on redacted extracts" costs one line and keeps the offer honest.
The line does three things at once. It tells a candidate what the job is this quarter, not in the abstract. It gives the hiring manager something to escalate with, because a published date has a witness. And it filters, gently: someone who will not take the job under the interim conditions withdraws before anyone spends an interview loop on them.
What it costs is a small amount of candor about an unfinished internal decision, which is the correct price. The alternative is discovering it at the ninety-day mark, when the new hire has built a private workflow nobody can support and the manager is explaining why the person hired for AI work has produced none. Structuring that first quarter deliberately is its own problem, handled in the first ninety days of an AI-heavy hire.
One more sequencing point for an executive: if the stack is more than a quarter away, the honest answer may be to train instead of recruiting. The tradeoff runs both ways and depends on how much of the work is already inside the building, which is the subject of hiring for AI skills versus training the team you have.
How to test for it when nobody can open the tool
Run the exercise on a transcript instead of a live tool. Hand the candidate a model's output that is confidently wrong in one place, plus the source material needed to catch it, and ask what they would do next. No endpoint gets called, nothing leaves the network, and what the exercise reads is judgment, which is what the blocked-stack version of the role runs on anyway.
The failure mode you are testing for is well documented. In the BCG field experiment, on one task deliberately placed outside the model's capability, consultants using GPT-4 were 19 points less likely to reach the correct answer than a control group of whom 84.5% got it, and the group given a prompt-engineering overview did worse than the group given none 4. One task, one sample, a 2023 model, so it is not evidence that AI makes people worse in general. It is evidence that people could not tell which side of the capability line a task was on, and that is the thing a transcript exercise reads directly.
Three practical notes. Use material from the occupation, not a general reasoning puzzle, because the skill being read is domain judgment applied to a machine's output. Give the same transcript to every candidate in the req. And score the check they describe, not their tone about AI: enthusiasm and skepticism both come in competent and incompetent versions, and only one of those distinctions is worth hiring on.
If the block turns out to be permanent, the transcript exercise stops being a workaround. The job it describes is one where a person reasons about machine output without operating the machine, which is exactly what the exercise puts in front of them.
Common questions
Is it legally risky to require AI skills for a job where the tools are blocked?
Ordinary employment-law exposure, not a special AI one. In the US, an employer whose practice is shown to cause a disparate impact has to demonstrate it is job related for the position in question, a test Congress wrote into 42 U.S.C. 2000e-2(k) in 1991 5. A skill the successful hire is forbidden to exercise is a weaker thing to defend on that test than a description of work the job does. Title VII is the only statute in view here; age and disability claims run under their own. Check the posting with counsel.
Our staff use AI anyway. Should the req reflect the real behavior or the official policy?
Neither, until somebody resolves the gap. A req written to the shadow reality invites a new hire to break a policy on their first week, and a req written to a policy nobody follows describes a job that does not exist. Take the mismatch to whoever owns the policy, get a date, and write the posting to whatever answer comes back.
Can we ask candidates about AI use in the interview if we block it internally?
That interview gets more interesting, not less. Ask what they stopped delegating after being burned, how they check a claim that matters, and what they would do in an environment with no approved assistant. Those answers describe judgment that transfers. Questions about specific tools do not transfer, and in a blocked environment they test something the person will never do at work.
How do I write the requirement without naming any vendor?
Describe the task and the check. "Takes an ambiguous brief, decides what has to be verified before it ships, and can show the verification" names a capability that survives a change of vendor, a change of model, and a change of policy. Vendor names date a posting within two quarters and read as a keyword list rather than a description of work.
Does an internal AI ban mean AI skills are not worth paying for?
It means the tool access is not what you are paying for. Postings that mention AI skills advertise higher salaries than postings that do not, and in 2024 over half of the postings asking for AI skills sat outside IT and computer science, so the demand is not confined to technical seats. Those are advertised figures from one posting database rather than a like-for-like wage estimate. The capability being paid for holds its value inside a blocked environment, because the scarce part was never the login.
Who should own the decision, security or talent?
Whoever can change the proxy rule owns the policy; talent owns the wording that follows from it. A req that contradicts the policy is not a turf problem, it is an unassigned one: no single person had both halves of the picture when it was published. Naming an owner and a review date is most of the fix.
References
- 1. Large Firms With at Least 20 Employees Biggest AI Users census.gov Supports the firm-level adoption baseline used to argue that a large employer probably has approved AI use somewhere already.
- 2. The Rapid Adoption of Generative AI (NBER Working Paper 32966) nber.org Supports the claim that worker-level AI use runs ahead of firm-level approval, which is what makes a blocked stack an unlogged one rather than an empty one.
- 3. Beyond the Buzz: Developing the AI Skills Employers Actually Need lightcast.io Supports the claim that employers already price AI skills into advertised pay, and that the demand reaches well beyond technical roles.
- 4. Navigating the Jagged Technological Frontier: Field Experimental Evidence of the Effects of Artificial Intelligence on Knowledge Worker Productivity and Quality (Working Paper 24-013) mitsloan.mit.edu Supports the transcript exercise, by showing that the measured failure is people not noticing which side of the capability line a task sits on.
- 5. 42 U.S.C. 2000e-2(k) - Burden of proof in disparate impact cases uscode.house.gov Supports the FAQ's statement of the federal disparate-impact test, which is the ground on which a requirement the successful hire cannot practice is hard to defend as job related.
5 sources, numbered by first appearance. How Olive sources claims
General guidance, not legal advice. Hiring rules differ by state and country and change often; check anything here against your own counsel before you act on it.
Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.